A new arXiv version 1 preprint dated 25 August 2026 examines whether networks could be paid to filter BGP hijack announcements through a system called BGPay. Its central result is a modeled one: public routing monitors were often numerous enough to provide evidence when a participant claimed to have filtered an attack, while the proposed reward formula favored a small group of high-cone ASes.
A payment system built around evidence
BGPay is built as an escrow protocol. Filterers and monitors commit their claims before either side reveals its information. A smart contract then pays based on evidence, rather than asking the owner of the affected prefix to decide whether filtering occurred. The proposal weights rewards by containment contribution, tying the payment calculation to the modeled impact of each filtering participant.
To test it, the authors ran AS-level Internet routing simulations using 7,988 high-confidence real prefix-hijack events from Cloudflare Radar and 1,018 unique hijacker ASes. The study modeled both longer-prefix and same-length-prefix hijacks within the same framework.
Propagation was modeled with the Gao-Rexford model and CAIDA AS relationships. Each AS exported only its selected best path, and ties were broken uniformly at random. The simulations included 799 ASes representing RIPE RIS and RouteViews public monitors. In modeled deployment runs, existing filtering was represented by 7,384 ASes with a perfect RoV Score.
Visibility was the strongest result
The clearest result concerned visibility. In cases where a provider AS was connected to a hijacker, the mean case had 648 monitors able to attest to filtering. In longer-prefix cases, at least one monitor could witness fraudulent non-filtering in 97% of cases. Those numbers make the evidence base look broad in the scenarios the model tested.
Fraud claims also had repeated coverage in a narrower test. For fraudulent claims by 1-hop providers and 2-hop provider-providers, the median hijack was observed by at least 300 monitors regardless of hijack type. Within the modeled scenarios, the evidence was usually repeated across many monitors rather than resting on a single observation.
The reward shortcut was less exact
The payment formula was less exact than the visibility result. The evaluation compared proxy-set size with Maximum Damage Potential, a modeled measure of containment impact. The Pearson correlation was 0.893 for longer-prefix hijacks, but 0.565 for same-length-prefix hijacks. That means the proxy tracked the impact measure much more closely in the first group.
Mean overlap between proxy-based and MDP-based containment-proportionate rewards was 78.4% for longer-prefix hijacks and 70.9% for same-length-prefix hijacks. The proxy therefore preserved most of the modeled allocation in both groups, but the match was weaker for same-length cases.
The authors identify the same-length result as a design weakness in the current rule. Because the relationship between proxy-set size and modeled impact was only moderate, the linear calculation can underpay filterers whose contribution is high and overpay those whose contribution is lower. The paper treats that mismatch as a limitation of the current proxy.
Most of the rewards went to a small group
Containment-proportionate rewards were highly concentrated. Ninety percent of the proportionately allocated reward went to just 4.5% of filtering ASes in longer-prefix cases and 5.5% in same-length cases. Ranked by customer-cone size, the top 1% earned 3.2 times as much as the next 9% in same-length cases and 1.8 times as much in longer-prefix cases.
That concentration is central to the proposal's incentive question. BGPay ties payment to containment contribution, and the model indicates that a small set of high-cone ASes received most of the modeled reward. The paper leaves the bounty needed to induce participation, and the market equilibrium that might result, for future work.
The numbers remain inside the model
At a modeled 50% adoption level for new filtering ASes, mean modeled hijack spread was 946.5 ASes for longer-prefix hijacks and 333.0 ASes for same-length-prefix hijacks. The paper reports reductions of 88.9% and 72.9%, respectively. Those figures are outputs of the simulated setting, and they do not resolve the bounty needed to induce participation.
The assumptions set a clear boundary around the result. BGPay assumes authenticated protocol messages and a monitor set, and an AS cannot be both a monitor and a filtering AS. The routing evaluation also relies on incomplete knowledge of Internet routing policies, a limitation the paper identifies alongside its other modeling assumptions.
The preprint therefore offers a modeled plausibility case for BGPay. Its simulations combine strong monitor visibility with a reward proxy that aligns reasonably well with modeled containment impact, especially for longer-prefix hijacks. They also expose two unresolved issues: weaker reward alignment for same-length-prefix cases and the economic conditions required for participation.
Paper data and sources
Original title: BGPay: An Incentive-Compatible Mechanism for BGP Hijack Filtering
Authors: Tomasz Sadowy, Constantine Doumanidis, Maria Apostolaki
Journal/Repository: arXiv
Status: Preprint, not yet peer-reviewed
First online: 2026-08-25
DOI: Not available
Original paper · Full text